CVE · Medium

CVE-2025-12965 — Magical Posts Display – Elementor Advanced Posts widgets [magical-posts-display] < 1.2.55

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12965 Magical Posts Display – Elementor Advanced Posts widgets [magical-posts-display] < 1.2.55 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.2.55 1.2.55 2025-12-11

CVE-2025-12965

A vulnerability exists in the Magical Posts Display plugin for WordPress, specifically in the Magical Posts Accordion widget, where user-supplied input is not properly sanitized or escaped, allowing an authenticated attacker with Author-level access or higher to inject malicious HTML code that will be executed when accessed by another user. This enables the attacker to inject arbitrary web scripts, which can then be executed by users visiting the affected page.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.